Showing posts with label Privacy International. Show all posts
Showing posts with label Privacy International. Show all posts

Tuesday, 29 January 2008

BREAKDOWN OF TRUST (re DATA SECURITY)

Hot on the heels of their excellent "2007 International Privacy Rankings", those good people at Privacy International have published figures showing a huge collapse of public trust in the Government's ability to hold our personal data securely.

Of course, of itself, this isn't particularly surprising or startling news. In the wake of the HMRC fiasco and the steady and recurring drip of revelations about the failure of individual Departments to protect our data - following on from the scandalous breach of the loss/theft of an RN laptop, this from the Ministry of Justice is merely the latest cock-up that has come to light - I am surprised that anyone has any faith whatsoever in a presumption that the Government can demonstrate even a smidgeon of competence in this field. No, what makes PI's report interesting are two associated consequences/repercussions.

First, it would be naive to assume that this breakdown of trust will confine itself to our interactions with Government. As PI's text points out, it will inevitably leech into the broader context of e-commerce generally - that is to say in both the public and private sectors (something confirmed, at least in part, by the FSA's recent Financial Risk Outlook): "At this stage it is not a simple matter to predict the potential financial impact of such a trend, but it is quite possible that the economy's growth could be inhibited if trust in data security continues to erode. The cost could easily run into billions of pounds per year". With the UK/world economy looking ever-more flaky (post N.Rock, the credit crunch, et al), the timing of this could not be worse, especially in terms of the direction of the psychology of the market (as per recent stock market volatility being a function of a lack of confidence). As Simon Davies says, this makes it a matter of considerable urgency that the Government should get a grip on the means to re-establish trust as soon as possible - although, as this piece from Rosemary Jay at out-law.com makes plain, the prospect of this looks exceedingly remote. Failure to do so could have the unintended consequence of entrenching the downturn in the economy more deeply.

This leads to my second point. I would guess that, whatever their public utterances, the various Government Ministers who have some measure of responsibility in this field are in a blind panic - if not worse, much worse - as to how to retrieve the position. In fact I have it on good authority that they have even resorted to approaching various privacy advocates with whom they have been conducting something akin to open warfare vis a vis ID cards for suggestions/advice. This would be laughable if it wasn't so serious! But their blind adherence to the Government's perceived wisdom about data management/Transformational Government/&c (all that tripe) means that their minds are closed to any sensible suggestions that may come their way. In their current mindset, all that is left to them is to shift the deck-chairs on the Great Bottler's good ship Titanic.

So, dear reader, whoop-de-do, things are going to get worse before they get better, not only in terms of data security/management but also the economy. And I reckon that, in the current climate, the best thing to do is to hold on to that distrust for a while as the best way of riding out the twin storms of Government incompetence over data security and the economic downturn.

Friday, 25 January 2008

UK = "ENDEMIC SURVEILLANCE SOCIETY"

I'm sure you will have noted that Privacy International published their "2007 International Privacy Ranking" a few weeks ago. Indeed there was some comment on the Report at the time (for example here from The Register and here from Spyblog) - and to this extent I concede that this is something of a 'catch-up' post. We can make of the Report's findings what we will. But the criteria that PI have deployed to make their assessments are appropriately objective. And on that basis it makes for decidedly uncomfortable reading.

Two things in particular strike me about the Report. First the trend in both the UK and the USA is undeniably towards ever greater erosion of our privacy rights. In other words the position defined by the Report is no blip on the radar. Rather, however well-intentioned some of the imperatives that underpin it may be (improvements to public services, prevention/detection of fraud, or what-have-you), it is an entrenched and relentless policy direction.

Second - and much more importantly - the right to privacy (and the attendant provision of adequate safeguards against the intrusion of the State into our daily lives) is a fundamental building block of a free society. Therefore, as sure as eggs is eggs, its emasculation makes us less free. If we stop to think about the somewhat woolly concept of 'The War on Terror', we can adopt a simplictic view that it is being 'fought' - I use the word advisedly - to protect our essential freedoms from the encroachment of the fundamentalist - perhaps even barbaric - ideology of the terrorist cause. The irony is that the assault on our privacy rights is justified in no small part on the basis of it being necessary in the interests of national security and to protect us from terrorist-inspired outrages. Accordingly I hope I'm not alone in supposing that it is perverse - some might even say asinine - to abate quintessential democratic freedoms (that of privacy in all its guises in particular) as a conscious and deliberate policy imperative when, to all intents and purposes, the declared aim is to defend them.

Now it may be that, at least superficially, privacy is less valued in societal terms than once it was. Innovations such as Facebook, MySpace, (perhaps even blogging) and others of this ilk are illustrative of how easily the (as it were) security of our privacy can be fragmented as a function and/or consequence of our interaction with the Internet and the Web. For my part I suspect that the vast majority of users of such sites are blissfully unaware of the way(s) in which their adherence to them either can or does undermine their privacy rights. In effect it is, in the main, an unintended - and, if considered properly and on the basis of full understanding, unwanted - consequence of 'buying into'/keeping pace with the latest technological advances. In other words it isn't so much that privacy is valued less; rather, in the context of how the Web works, it is less understood and/or misunderstood. What matters here is that the societal changes wrought by the Web/Internet make it more, not less, important that the right to privacy should be defended.

The upshot is that the policy direction here as espoused by our lords and masters (in both the UK and US) is completely and utterly wrong. It is absolute garbage. Methinks, time for a change (not least of direction)!

Wednesday, 12 December 2007

PLOD AT THE DOOR OF No.10 ... AGAIN?

Now here's a thing!

As we know Richard Thomas, the Information Commissioner, has indicated that he is in favour of amendment of the Data Protection Act. Specifically, he is calling for a new criminal offence although quite what form this should take is perhaps less clear. But let us assume that it is wrapped around the phraseology "knowingly or recklessly failing to comply with the data protection principles". That would just about cover all the appropriate bases. And, let us assume that Parliament in its wisdom does in fact put this on the statute book.

Well, we also now know that the Great Bottler, when he was still Chancellor, was alerted to the fact that "data protection procedures governing the child benefit database" were as leaky as a sieve back in 2004 (reports here and here). And yet (so it seems) he chose to do bugger all about it. I know we're talking hypotheticals here but I reckon that sort of behaviour is a pretty good fit with "knowingly or recklessly failing to comply with the data protection principles". In other words, given a law change, the Great Bottler - and, presumably, the current incumbent, Darling - would be in the frame for a visit from Plod, presumably under caution!

You've got to reckon that Nu-Labour, following the indignity of Bliar being the first serving PM to be interviewed under caution over cash-for-peerages, are dead keen not to put themselves in a position where that could happen again - in fact, it'd be worse because I reckon Plod would be interested in the actions of both of the holders of the two highest offices in the land (the PM and the Chancellor of the Exchequer). And so it seems. Certainly it's what I read in to the sub-text of this written answer to Baroness Noakes last week.

But, in reality, this may offer them scant comfort. Those excellent fellows over at Privacy International appear to be seriously contemplating an action against the UK Government even as the law currently stands. Quite right too. Needless to say, their chances of prosecuting such a case would improve immeasurably if you, dear reader, felt inclined to offer your support. So, should you feel disposed so to do, please feel free to contact Simon Davies at simon@privacy.org. I'm sure that for a whole bunch of us there would be no better Xmas present than the prospect of the Great Bottler and his sidkick, Darling, having a little visit from the boys in blue!!!